{ "type": "bundle", "id": "bundle--559f66e6-6e10-468f-9025-81c0950d210b", "objects": [ { "type": "identity", "spec_version": "2.1", "id": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-08-18T08:39:34.000Z", "modified": "2015-08-18T08:39:34.000Z", "name": "CthulhuSPRL.be", "identity_class": "organization" }, { "type": "report", "spec_version": "2.1", "id": "report--559f66e6-6e10-468f-9025-81c0950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-08-18T08:39:34.000Z", "modified": "2015-08-18T08:39:34.000Z", "name": "OSINT OSX/Pintsized Backdoor Additional Details by Zataz / Eric Romang", "published": "2015-08-18T12:19:10Z", "object_refs": [ "observed-data--559f66fe-4e38-43b8-9c23-f3af950d210b", "url--559f66fe-4e38-43b8-9c23-f3af950d210b", "x-misp-attribute--559f671e-e834-4cb1-a733-82a8950d210b", "x-misp-attribute--559f671e-03f8-4807-b1a5-82a8950d210b", "indicator--55d2ee49-0edc-47d7-87d8-966f950d210b", "indicator--55d2ee49-79f4-4b58-a9c2-966f950d210b", "indicator--55d2ee4a-5ad8-4a53-bd24-966f950d210b", "indicator--55d2ee4a-9450-460a-899e-966f950d210b", "indicator--55d2ee4a-e3b8-4646-aecb-966f950d210b", "indicator--55d2ee4a-9ef8-4190-82dc-966f950d210b", "indicator--55d2ee4a-e8d4-4d2a-9d47-966f950d210b", "indicator--55d2ee4b-8704-4c0c-96e1-966f950d210b", "indicator--55d2ee4b-cdd8-4dd3-b30b-966f950d210b", "indicator--55d2ee4b-6760-49d4-ba62-966f950d210b", "indicator--55d2ee4b-d988-42bf-a85b-966f950d210b", "indicator--55d2ee4b-9790-4076-b9bc-966f950d210b", "indicator--55d2ef42-1e4c-4a13-b5d7-a4cf950d210b", "indicator--55d2ef42-5ab4-4bb0-9244-a4cf950d210b", "indicator--55d2ef43-d6ec-490f-8d0e-a4cf950d210b", "indicator--55d2ef43-4ba0-432b-a3dc-a4cf950d210b", "indicator--55d2ef43-2a88-4744-9d97-a4cf950d210b", "indicator--55d2ef43-2d18-40c6-a939-a4cf950d210b", "indicator--55d2ef43-3bc0-4e99-921a-a4cf950d210b", "indicator--55d2ef44-aee4-47e7-a16d-a4cf950d210b", "indicator--55d2ef44-05f4-40aa-98c9-a4cf950d210b", "indicator--55d2ef44-1ba8-4b59-8038-a4cf950d210b", "indicator--55d2ef44-4a50-44b7-be0f-a4cf950d210b", "indicator--55d2ef44-0200-4e04-a99e-a4cf950d210b", "indicator--55d2ef45-7fe4-48b0-830d-a4cf950d210b", "indicator--55d2ef45-ccd8-488c-add3-a4cf950d210b", "indicator--55d2ef45-4ad4-48df-a552-a4cf950d210b", "indicator--55d2ef45-aaec-426e-bd31-a4cf950d210b", "indicator--55d2ef45-8494-4cf8-b4f3-a4cf950d210b" ], "labels": [ "Threat-Report", "misp:tool=\"MISP-STIX-Converter\"", "type:OSINT" ], "object_marking_refs": [ "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9" ] }, { "type": "observed-data", "spec_version": "2.1", "id": "observed-data--559f66fe-4e38-43b8-9c23-f3af950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-07-10T06:32:30.000Z", "modified": "2015-07-10T06:32:30.000Z", "first_observed": "2015-07-10T06:32:30Z", "last_observed": "2015-07-10T06:32:30Z", "number_observed": 1, "object_refs": [ "url--559f66fe-4e38-43b8-9c23-f3af950d210b" ], "labels": [ "misp:type=\"link\"", "misp:category=\"External analysis\"" ] }, { "type": "url", "spec_version": "2.1", "id": "url--559f66fe-4e38-43b8-9c23-f3af950d210b", "value": "http://eromang.zataz.com/2013/03/24/osx-pintsized-backdoor-additional-details/" }, { "type": "x-misp-attribute", "spec_version": "2.1", "id": "x-misp-attribute--559f671e-e834-4cb1-a733-82a8950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-07-10T06:33:02.000Z", "modified": "2015-07-10T06:33:02.000Z", "labels": [ "misp:type=\"text\"", "misp:category=\"External analysis\"" ], "x_misp_category": "External analysis", "x_misp_type": "text", "x_misp_value": "Morpho" }, { "type": "x-misp-attribute", "spec_version": "2.1", "id": "x-misp-attribute--559f671e-03f8-4807-b1a5-82a8950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-07-10T06:33:02.000Z", "modified": "2015-07-10T06:33:02.000Z", "labels": [ "misp:type=\"text\"", "misp:category=\"External analysis\"" ], "x_misp_category": "External analysis", "x_misp_type": "text", "x_misp_value": "Wild Neutron" }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--55d2ee49-0edc-47d7-87d8-966f950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-08-18T08:35:21.000Z", "modified": "2015-08-18T08:35:21.000Z", "pattern": "[file:hashes.MD5 = '7fe4149b82516ae43938de6b8316ed84']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2015-08-18T08:35:21Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Payload delivery" } ], "labels": [ "misp:type=\"md5\"", "misp:category=\"Payload delivery\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--55d2ee49-79f4-4b58-a9c2-966f950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-08-18T08:35:21.000Z", "modified": "2015-08-18T08:35:21.000Z", "pattern": "[file:hashes.MD5 = '2e35b9a683ccc2408fef5ca575abf0e6']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2015-08-18T08:35:21Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Payload delivery" } ], "labels": [ "misp:type=\"md5\"", "misp:category=\"Payload delivery\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--55d2ee4a-5ad8-4a53-bd24-966f950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-08-18T08:35:22.000Z", "modified": "2015-08-18T08:35:22.000Z", "pattern": "[file:hashes.MD5 = '27f241c64303e4e2d1d94d3143a48eb9']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2015-08-18T08:35:22Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Payload delivery" } ], "labels": [ "misp:type=\"md5\"", "misp:category=\"Payload delivery\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--55d2ee4a-9450-460a-899e-966f950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-08-18T08:35:22.000Z", "modified": "2015-08-18T08:35:22.000Z", "pattern": "[file:hashes.MD5 = '2b9b84f0612d6f9d7efb705dd7522f83']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2015-08-18T08:35:22Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Payload delivery" } ], "labels": [ "misp:type=\"md5\"", "misp:category=\"Payload delivery\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--55d2ee4a-e3b8-4646-aecb-966f950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-08-18T08:35:22.000Z", "modified": "2015-08-18T08:35:22.000Z", "pattern": "[file:hashes.MD5 = '34cee92669e0c60a9dbafae7319f49db']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2015-08-18T08:35:22Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Payload delivery" } ], "labels": [ "misp:type=\"md5\"", "misp:category=\"Payload delivery\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--55d2ee4a-9ef8-4190-82dc-966f950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-08-18T08:35:22.000Z", "modified": "2015-08-18T08:35:22.000Z", "pattern": "[file:hashes.MD5 = 'd3f151b246deb74890c612606c6ad044']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2015-08-18T08:35:22Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Payload delivery" } ], "labels": [ "misp:type=\"md5\"", "misp:category=\"Payload delivery\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--55d2ee4a-e8d4-4d2a-9d47-966f950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-08-18T08:35:22.000Z", "modified": "2015-08-18T08:35:22.000Z", "pattern": "[file:hashes.MD5 = 'f419dfb35a0d220c4c53c4a087c91d5e']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2015-08-18T08:35:22Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Payload delivery" } ], "labels": [ "misp:type=\"md5\"", "misp:category=\"Payload delivery\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--55d2ee4b-8704-4c0c-96e1-966f950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-08-18T08:35:23.000Z", "modified": "2015-08-18T08:35:23.000Z", "pattern": "[file:hashes.MD5 = '59424d4a567ae809f96afc56d22892b2']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2015-08-18T08:35:23Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Payload delivery" } ], "labels": [ "misp:type=\"md5\"", "misp:category=\"Payload delivery\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--55d2ee4b-cdd8-4dd3-b30b-966f950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-08-18T08:35:23.000Z", "modified": "2015-08-18T08:35:23.000Z", "pattern": "[file:hashes.MD5 = '0ec55685affc322a5d7be2e9ca1f9cbf']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2015-08-18T08:35:23Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Payload delivery" } ], "labels": [ "misp:type=\"md5\"", "misp:category=\"Payload delivery\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--55d2ee4b-6760-49d4-ba62-966f950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-08-18T08:35:23.000Z", "modified": "2015-08-18T08:35:23.000Z", "pattern": "[file:hashes.MD5 = '3a861b8526e397b3684a99f363ec145b']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2015-08-18T08:35:23Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Payload delivery" } ], "labels": [ "misp:type=\"md5\"", "misp:category=\"Payload delivery\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--55d2ee4b-d988-42bf-a85b-966f950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-08-18T08:35:23.000Z", "modified": "2015-08-18T08:35:23.000Z", "pattern": "[file:hashes.MD5 = '1582d68144de2808b518934f0a02bfd6']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2015-08-18T08:35:23Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Payload delivery" } ], "labels": [ "misp:type=\"md5\"", "misp:category=\"Payload delivery\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--55d2ee4b-9790-4076-b9bc-966f950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-08-18T08:35:23.000Z", "modified": "2015-08-18T08:35:23.000Z", "pattern": "[file:hashes.MD5 = '622fc8b7daf425aed7f9ffa97e30c611']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2015-08-18T08:35:23Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Payload delivery" } ], "labels": [ "misp:type=\"md5\"", "misp:category=\"Payload delivery\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--55d2ef42-1e4c-4a13-b5d7-a4cf950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-08-18T08:39:30.000Z", "modified": "2015-08-18T08:39:30.000Z", "pattern": "[domain-name:value = 'ads.digitalinsight-ltd.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2015-08-18T08:39:30Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--55d2ef42-5ab4-4bb0-9244-a4cf950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-08-18T08:39:30.000Z", "modified": "2015-08-18T08:39:30.000Z", "pattern": "[domain-name:value = 'ak.fbcbn.net']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2015-08-18T08:39:30Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--55d2ef43-d6ec-490f-8d0e-a4cf950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-08-18T08:39:31.000Z", "modified": "2015-08-18T08:39:31.000Z", "pattern": "[domain-name:value = 'cache.cloudbox-storage.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2015-08-18T08:39:31Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--55d2ef43-4ba0-432b-a3dc-a4cf950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-08-18T08:39:31.000Z", "modified": "2015-08-18T08:39:31.000Z", "pattern": "[domain-name:value = 'cloudbox-storage.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2015-08-18T08:39:31Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"domain\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--55d2ef43-2a88-4744-9d97-a4cf950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-08-18T08:39:31.000Z", "modified": "2015-08-18T08:39:31.000Z", "pattern": "[domain-name:value = 'clust12-akmai.net']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2015-08-18T08:39:31Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"domain\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--55d2ef43-2d18-40c6-a939-a4cf950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-08-18T08:39:31.000Z", "modified": "2015-08-18T08:39:31.000Z", "pattern": "[domain-name:value = 'corp-appl.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2015-08-18T08:39:31Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"domain\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--55d2ef43-3bc0-4e99-921a-a4cf950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-08-18T08:39:31.000Z", "modified": "2015-08-18T08:39:31.000Z", "pattern": "[domain-name:value = 'digitalinsight-ltd.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2015-08-18T08:39:31Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"domain\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--55d2ef44-aee4-47e7-a16d-a4cf950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-08-18T08:39:32.000Z", "modified": "2015-08-18T08:39:32.000Z", "pattern": "[domain-name:value = 'fb.clust12-akmai.net']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2015-08-18T08:39:32Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--55d2ef44-05f4-40aa-98c9-a4cf950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-08-18T08:39:32.000Z", "modified": "2015-08-18T08:39:32.000Z", "pattern": "[domain-name:value = 'fbcbn.net']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2015-08-18T08:39:32Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"domain\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--55d2ef44-1ba8-4b59-8038-a4cf950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-08-18T08:39:32.000Z", "modified": "2015-08-18T08:39:32.000Z", "pattern": "[domain-name:value = 'fbu.clust12-akmai.net']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2015-08-18T08:39:32Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--55d2ef44-4a50-44b7-be0f-a4cf950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-08-18T08:39:32.000Z", "modified": "2015-08-18T08:39:32.000Z", "pattern": "[domain-name:value = 'img.digitalinsight-ltd.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2015-08-18T08:39:32Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--55d2ef44-0200-4e04-a99e-a4cf950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-08-18T08:39:32.000Z", "modified": "2015-08-18T08:39:32.000Z", "pattern": "[domain-name:value = 'jdk-update.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2015-08-18T08:39:32Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"domain\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--55d2ef45-7fe4-48b0-830d-a4cf950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-08-18T08:39:33.000Z", "modified": "2015-08-18T08:39:33.000Z", "pattern": "[domain-name:value = 'pop.digitalinsight-ltd.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2015-08-18T08:39:33Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--55d2ef45-ccd8-488c-add3-a4cf950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-08-18T08:39:33.000Z", "modified": "2015-08-18T08:39:33.000Z", "pattern": "[domain-name:value = 'static.ak.fbcbn.net']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2015-08-18T08:39:33Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--55d2ef45-4ad4-48df-a552-a4cf950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-08-18T08:39:33.000Z", "modified": "2015-08-18T08:39:33.000Z", "pattern": "[domain-name:value = 'ww1.jdk-update.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2015-08-18T08:39:33Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--55d2ef45-aaec-426e-bd31-a4cf950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-08-18T08:39:33.000Z", "modified": "2015-08-18T08:39:33.000Z", "pattern": "[domain-name:value = 'www.digitalinsight-ltd.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2015-08-18T08:39:33Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--55d2ef45-8494-4cf8-b4f3-a4cf950d210b", "created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f", "created": "2015-08-18T08:39:33.000Z", "modified": "2015-08-18T08:39:33.000Z", "pattern": "[domain-name:value = 'www.jdk-update.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2015-08-18T08:39:33Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "marking-definition", "spec_version": "2.1", "id": "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9", "created": "2017-01-20T00:00:00.000Z", "definition_type": "tlp", "name": "TLP:WHITE", "definition": { "tlp": "white" } } ] }